coinhld-helpp[.]framer[.]website
“Sign In to Coinbase Pro | Professional Crypto Trading Platform”
coinhld-helpp.framer.website — Contenido no disponible. Suplantación de marca: Coinbase; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 16/95 (ChainPatrol, Criminal IP, alphaMountain.ai, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Registrador: CSC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain coinhld-helpp.framer.website was registered on November 19, 2021 through CSC Corporate Domains, Inc. and is hosted on Amazon Web Services under ASN 16509 (Amazon.com, Inc.), resolving to the IPv4 address 35.71.142.77 located in the United States. The site presented a TLS certificate issued by Let’s Encrypt (E7), indicating encrypted HTTPS support, and the server responded with HTTP status 404 at the time of analysis. The page title returned by the web server was "Sign In to Coinbase Pro | Professional Crypto Trading Platform," directly referencing the Coinbase brand, confirming a brand‑impersonation intent.
Technical fingerprints show the use of Framer Sites, React, HSTS, and HTTP/3, all consistent with modern web‑hosting stacks but not indicative of malicious payloads themselves. VirusTotal scanned the domain and recorded 16 detections out of 95 security‑vendor engines, providing independent confirmation of its malicious nature. The domain appears on one public security blocklist and is explicitly listed by PhishDestroy as a blocked entry, reinforcing its classification as a crypto‑related scam.
Current operational status is offline, with the site returning 404, yet the infrastructure artifacts remain observable. Defensive recommendations include adding the domain and its associated IP address (35.71.142.77) to network blocklists, monitoring DNS queries for the listed nameservers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, ns-792.awsdns) to detect any future resurrection, and enforcing URL filtering rules that flag the exact page title string associated with Coinbase. Analysts should also update threat‑intel feeds with the domain’s registration details, SSL fingerprint, and the observed detection count to improve cross‑organization awareness of similar brand‑impersonation campaigns.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.